F5-K000159824: High severity F5 NGINX Plus vulnerability
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response from an upstream proxied server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000159824?
The severity of F5-K000159824 is considered critical due to the potential for man-in-the-middle attacks.
How do I fix F5-K000159824?
To fix F5-K000159824, upgrade your NGINX Plus or NGINX Open Source to the latest recommended version from F5.
Which versions of NGINX are affected by F5-K000159824?
F5-K000159824 affects NGINX Plus version 32 and NGINX Open Source versions from 1.3.0 to 1.29.4.
Is the NGINX Ingress Controller affected by F5-K000159824?
Yes, F5-K000159824 impacts specific versions of the NGINX Ingress Controller ranging from 3.4.0 to 5.3.2.
What type of attack does F5-K000159824 vulnerability enable?
F5-K000159824 enables man-in-the-middle attacks, allowing an attacker to inject plain text data into the communication.